Sploitus

CVE-2025-58034

9 known exploits for CVE-2025-58034

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Affected products
Fortiweb
Fortinet Fortiweb
< 7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.2
CVSS 3.1
7.2 HIGH
EPSS
55.6% (99th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2025-11-18

Fix

Upgrade to FortiWeb version 8.0.2 or above Upgrade to FortiWeb version 7.6.6 or above Upgrade to FortiWeb version 7.4.11 or above Upgrade to FortiWeb version 7.2.12 or above Upgrade to FortiWeb version 7.0.12 or above

CVE-2025-58034 at NVD
Authoritative description, scoring and affected products

9 known exploits for CVE-2025-58034

Proof-of-concept code and exploit modules indexed by Sploitus